Compare
Jern Cloud vs GitHub Copilot cloud agent.
The closest comparison, because both live on GitHub: assign an issue or leave a comment, and a pull request comes back. Copilot's agent runs in an ephemeral GitHub Actions environment behind a firewall; Jern's runs on its own machine under a policy the repository owns, with your model key and a receipt. This page is written from GitHub's public documentation as of September 8, 2026 and from ours; if we have something wrong, tell us and we will fix it.
Side by side
| Jern Cloud | Copilot cloud agent | |
|---|---|---|
| Where the agent runs | One machine per attempt, created for it and destroyed afterwards, with Linux namespaces and seccomp inside the guest boundary. Machine time is metered per size. | An ephemeral development environment powered by GitHub Actions, destroyed after the session, with automated security scanning. |
| What starts work | The dashboard, an issue label, a /jern comment, a failed check on the session's pull request, a schedule, or the MCP server from an editor. | Assigning an issue to Copilot, the agents panel on GitHub.com, Copilot Chat, VS Code, an @copilot mention on a pull request, security campaigns, Slack and Teams in preview, and automations on a schedule or on events such as an issue being opened. |
| Where the rules live | A file in the repository, protected by your reviewers and pinned by digest for the session. The runtime enforces it at every tool call: paths that may change, a blast radius in files and lines, protected paths, the shell commands that run without asking, services, and hosts. | Repository custom instructions and custom agents guide the model; the firewall and the Actions environment bound it. There is no file-level edit boundary or blast radius enforced against the model; branch protection applies to the pull request. |
| Network while it works | During the run, one route: a relay to the Jern gateway. Named hosts from the baseline are readable through a tool that counts every contact on the receipt. Package indexes are reachable during setup only. | A firewall on by default with a recommended allowlist of package registries, container registries, and certificate authorities, configurable per organization and repository. GitHub's docs note it applies only to processes the agent starts through its Bash tool, not to MCP servers or setup steps, and that sophisticated attacks may bypass it. |
| Credentials the agent holds | No GitHub token or model key. Checkout, evidence upload, checkpoints, and publication each use a short-lived credential the runner holds outside the agent process, and the gateway holds your model key. Repository secrets reach it only when an administrator stores them. | A GitHub token scoped to the repository for the session's work, plus any secrets you place in the environment for setup steps or MCP servers. |
| What the reviewer gets | A receipt on every pull request as a check: tokens against cap, files against the blast radius, policy decisions, hosts contacted, the sandbox. Behind it, the exact trace, encrypted before it reaches a database. | The pull request, every step visible as a commit, session logs, and a warning in the pull request when the firewall blocked a request. |
| Can it merge? | Never. One pull request per session on an isolated branch; your branch protection and reviewers apply. | No. Copilot opens the pull request; a person reviews and merges, and workflows on its pull requests wait for a person's approval. |
| Models and billing | Your own Anthropic, OpenAI, Gemini, or Fireworks key; tokens bill to your provider account and the gateway meters them from the provider's usage report. $19 per workspace per month plus machine hours, after 30 days free. | GitHub's models, billed in Copilot AI credits with your Copilot plan, plus the Actions minutes the environment uses. No customer key. |
| Self-hosted | Jern's cloud only. Self-hosted runners are on the roadmap. | The environment runs on GitHub's Actions runners. |
| Breadth | GitHub only. Python, Node, .NET, and Java environments. The runtime is open source, Apache-2.0. The agent that runs in a session is the one you can read and run on a laptop. | Everything GitHub already is: issues, projects, security campaigns, code review, Chat, the CLI and SDK, and the desktop app. Research and plan before writing code. Custom agents per task. Closed source. |
Which to choose
Choose Copilot cloud agent when you already pay for Copilot and want the agent inside the tools you use, with the least setup. It is the default, and for a repository whose risk is small it is enough. Choose Jern Cloud when the repository is the kind where the question after every agent change is what it was allowed to do: the policy is a file your reviewers protect, the runtime refuses an edit outside it, the agent holds no token at all, the network is closed rather than filtered, and the pull request carries a receipt that says all of that. Jern also runs on your own model key, so the tokens are priced by your provider, and the agent it runs is open source.
What Jern does not do
No browser, no desktop, no Slack, no GitLab or Bitbucket, no self-hosted runners yet, and four language environments. Our isolation relies on Fly.io's guest boundary plus namespaces and seccomp inside it, and an independent test of that boundary is planned and not yet published. Your messages and the agent's replies are stored in plaintext so the dashboard can show them; evidence is encrypted, conversation text is not. The security page lists what is not defended against.
See it
The recipes are real sessions on the public demo repository with their pull requests and receipts. A session on your own repository takes a sign-in with GitHub and a provider key; the first 30 days are free.
Sources
Read on September 8, 2026. Products change; the sources are linked so you can check the current state.